A Hybrid Training-time and Run-time Defense Against Adversarial Attacks in Modulation Classification

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Zhang, Lu, Lambotharan, Sangarapillai, Zheng, Gan, Liao, Guisheng, Demontis, Ambra, Roli, Fabio
Formato: Preprint
Publicado: 2024
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866911949394018304
author Zhang, Lu
Lambotharan, Sangarapillai
Zheng, Gan
Liao, Guisheng
Demontis, Ambra
Roli, Fabio
author_facet Zhang, Lu
Lambotharan, Sangarapillai
Zheng, Gan
Liao, Guisheng
Demontis, Ambra
Roli, Fabio
contents Motivated by the superior performance of deep learning in many applications including computer vision and natural language processing, several recent studies have focused on applying deep neural network for devising future generations of wireless networks. However, several recent works have pointed out that imperceptible and carefully designed adversarial examples (attacks) can significantly deteriorate the classification accuracy. In this paper, we investigate a defense mechanism based on both training-time and run-time defense techniques for protecting machine learning-based radio signal (modulation) classification against adversarial attacks. The training-time defense consists of adversarial training and label smoothing, while the run-time defense employs a support vector machine-based neural rejection (NR). Considering a white-box scenario and real datasets, we demonstrate that our proposed techniques outperform existing state-of-the-art technologies.
format Preprint
id arxiv_https___arxiv_org_abs_2407_06807
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle A Hybrid Training-time and Run-time Defense Against Adversarial Attacks in Modulation Classification
Zhang, Lu
Lambotharan, Sangarapillai
Zheng, Gan
Liao, Guisheng
Demontis, Ambra
Roli, Fabio
Artificial Intelligence
Motivated by the superior performance of deep learning in many applications including computer vision and natural language processing, several recent studies have focused on applying deep neural network for devising future generations of wireless networks. However, several recent works have pointed out that imperceptible and carefully designed adversarial examples (attacks) can significantly deteriorate the classification accuracy. In this paper, we investigate a defense mechanism based on both training-time and run-time defense techniques for protecting machine learning-based radio signal (modulation) classification against adversarial attacks. The training-time defense consists of adversarial training and label smoothing, while the run-time defense employs a support vector machine-based neural rejection (NR). Considering a white-box scenario and real datasets, we demonstrate that our proposed techniques outperform existing state-of-the-art technologies.
title A Hybrid Training-time and Run-time Defense Against Adversarial Attacks in Modulation Classification
topic Artificial Intelligence
url https://arxiv.org/abs/2407.06807